Aggregator
CVE-2022-4508 | ConvertKit Plugin up to 2.0.4 on WordPress Shortcode Attribute cross site scripting
CVE-2022-4549 | Tickera Plugin up to 3.5.0.x on WordPress Setting cross-site request forgery
CVE-2023-22280 | Mahoroba MAHO-PBX NetDevancer prior 1.11.00 os command injection
CVE-2021-0920 | Google Android Kernel race condition (A-196926917)
More From Our Main Blog: IngressNightmare | Critical Unauthenticated RCE Vulnerabilities in Kubernetes Ingress NGINX
We share actionable mitigation and detection strategies against IngressNightmare so you can protect against possible exploitation in runtime.
The post IngressNightmare | Critical Unauthenticated RCE Vulnerabilities in Kubernetes Ingress NGINX appeared first on SentinelOne.
CVE-2025-3299 | PHPGurukul Men Salon Management System 1.0 /appointment.php Name sql injection
CVE-2025-3298 | SourceCodester Online Eyewear Shop 1.0 Registration Master.php?f=save_product email access control
CVE-2025-3297 | SourceCodester Online Eyewear Shop 1.0 Master.php?f=save_product brand cross site scripting
CVE-2025-3296 | SourceCodester Online Eyewear Shop 1.0 Users.php?f=delete_customer ID sql injection
Submit #550185: PHPGurukul Men Salon Management System V1.0 SQL Injection [Accepted]
Submit #550010: sourcecodester Online Eyewear Shop Website v1.0 Any user registration [Accepted]
Submit #549982: sourcecodester Online Eyewear Shop Website v1.0 XSS [Accepted]
Submit #549932: sourcecodester Online Eyewear Shop Website v1.0 SQL Injection [Accepted]
CVE-2025-0839 | ZoomIt ZoomSounds Plugin up to 6.91 on WordPress Shortcode cross site scripting
23andMe Bankruptcy: Should DNA Data Go to the Top Bidder?
The financial collapse of personal genomics giant 23andMe raises an urgent question: What happens to your most intimate data when the company holding it goes bankrupt? Jonathan Armstrong, partner at Punter Southall Law, warns of cascading legal, ethical and security consequences.
CVE-2025-1233 | AlThemist Lafka Plugin up to 7.1.0 on WordPress Option Update lafka_options_upload authorization
CVE-2024-13776 | ZoomSounds Plugin up to 6.91 on WordPress Setting dzsap_delete_notice seen authorization
Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how threat actors are leveraging fake recruitment emails to distribute malicious payloads. The attackers impersonated Dev.to, a prominent developer community, and lured victims with promises of lucrative job offers. Instead of attaching malware directly to emails, they provided a BitBucket link […]
The post Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.